Azure App Service上Node.js应用无法从Key Vault取密钥:无MSI凭证
Azure App Service(Linux)Node.js 20 LTS应用Key Vault密钥获取失败问题
在Azure App Service(Linux)上部署的Node.js 20 LTS应用,尝试从Azure Key Vault获取密钥时触发CredentialUnavailableError,错误信息为:
ManagedIdentityCredential: Authentication failed. Message ManagedIdentityCredential - No MSI credential available
相关代码片段
const { DefaultAzureCredential } = require("@azure/identity"); const { SecretClient } = require("@azure/keyvault-secrets"); const keyVaultName = process.env.KEY_VAULT_NAME; const keyVaultUrl = `https://${keyVaultName}.vault.azure.net`; async function loadSecrets() { try { require('dotenv').config(); console.log('Starting loadSecrets function'); console.log('NODE_ENV:', process.env.NODE_ENV); console.log('DATABASE_URL:', process.env.DATABASE_URL); console.log('KEY_VAULT_NAME:', process.env.KEY_VAULT_NAME); if (process.env.NODE_ENV === 'production') { console.log('Production environment detected. Attempting to load secrets from Key Vault.'); console.log('Creating DefaultAzureCredential...'); const credential = new DefaultAzureCredential(); console.log('DefaultAzureCredential created successfully'); const keyVaultUrl = `https://${process.env.KEY_VAULT_NAME}.vault.azure.net`; console.log('Key Vault URL:', keyVaultUrl); console.log('Creating SecretClient...'); const secretClient = new SecretClient(keyVaultUrl, credential); console.log('SecretClient created successfully'); console.log('Fetching secrets...'); process.env.CLAUDE_API_KEY = (await secretClient.getSecret('CLAUDE-API-KEY')).value; console.log('CLAUDE-API-KEY fetched successfully'); // ... [other secret fetching operations] ... console.log('All secrets loaded successfully from Key Vault'); } else { console.log('Non-production environment. Skipping Key Vault secret loading.'); } } catch (error) { console.error('Error in loadSecrets function:'); console.error('Error name:', error.name); console.error('Error message:', error.message); // ... [additional error logging] ... throw error; } } // Load secrets before starting the server loadSecrets().then(() => { // Server setup and route definitions... }).catch(error => { console.error('Failed to load secrets:', error); process.exit(1); });
已执行的排查操作
- 确认App Service已启用系统分配托管身份
- 已为该托管身份在Key Vault的IAM中分配“Key Vault Secrets User”角色(Key Vault采用RBAC权限模型)
- 验证App Service配置中KEY_VAULT_NAME环境变量已正确设置
- 尝试改用DefaultAzureCredential替代ManagedIdentityCredential
- 确认Key Vault中存在对应名称的密钥
疑问
- 为何已启用托管身份仍出现“No MSI credential available”错误?
- 是否存在遗漏的配置或权限项?
- 如何排查托管身份的认证流程?
- Node.js 20 LTS与Azure Identity SDK是否存在已知兼容问题?
- 如何在运行时验证托管身份与App Service的关联状态?
内容的提问来源于stack exchange,提问作者user26559929
相关产品推荐
相关产品推荐

